Community Trust ScoreVerified
North Korea did it again. Blockchain analytics firm Chainalysis has tied the $387 million hack on crypto exchange Bitget directly to North Korean-linked hacking groups — and the theft is now a major chunk of the over $1 billion in crypto stolen by those same groups so far in 2026.
Why It Matters
The significant hack on Bitget underscores the ongoing vulnerabilities within centralized cryptocurrency exchanges, particularly as North Korean hacking groups continue to exploit these weaknesses for large-scale thefts. This incident not only highlights the urgent need for enhanced security measures in the crypto sector but also raises concerns about the potential for increased regulatory scrutiny on exchanges, which could impact market operations and investor confidence. As such, the theft contributes to the broader narrative of cybersecurity risks that plague the cryptocurrency ecosystem, potentially influencing user behavior and market dynamics moving forward.
The breach hit on September 24. Within the first three hours, $387 million moved out of Bitget in 23 separate transactions, spread across four networks: Ethereum took the biggest slice at 49.7%, XRP followed at 40.8%, Zcash got 7.6%, and Tron picked up the remaining 1.8%. Fast, clean, and clearly planned well in advance. Chainalysis has since been working alongside Bitget and law enforcement to trace the funds as they moved through a maze of blockchains, swap services, and liquidity protocols.
The stolen XRP didn’t just sit there.
It got routed through a cross-chain liquidity protocol, converted into Bitcoin, and pushed into addresses the attackers control. The broader laundering operation leaned on cross-chain liquidity and messaging protocols, instant swaps, and dedicated laundering services — a layered approach designed to make tracing a nightmare. And it kind of worked, at least for a while.
AI Cut 20 Hours of Work to Under 10 Minutes
Chainalysis didn’t just rely on human analysts. The firm used its own in-house AI technology to speed up the investigation, compressing what would’ve been over 20 hours of manual reconciliation into under 10 minutes. That’s a pretty significant jump. Human oversight stayed in the loop throughout — the AI didn’t run solo — but the speed difference is hard to ignore when you’re chasing funds moving across multiple chains in real time.
Other firms backed up the North Korea angle. Bitget CEO Gracy Chen and blockchain analytics company Elliptic both flagged patterns consistent with North Korean hacker activity, adding weight to Chainalysis’s assessment. No one seems to be disputing the attribution at this point.
Swap Services Split on How to React
Not every platform handled the situation the same way. Near Intents moved fast, blocking over $50 million in swaps linked to the hacker. Then, somewhat ironically, Near Intents itself got hit by a hack. Thorchain took a different path — it kept processing transactions without stopping, which drew attention given the circumstances. The contrast between the two platforms pretty much sums up how fragmented the response from the broader crypto infrastructure was.
The attackers also tried to bury funds in Zcash’s shielded pool. Zcash’s privacy features make tracing harder, and that’s probably exactly why it was in the mix. Blockchain observers could still watch the hacker’s movements play out in real time on the public chains, even when the trail got murkier in the shielded pool.
Stablecoin issuers stepped in too. Circle and Tether froze roughly $318,000 in stablecoins tied to the stolen assets. It’s a small fraction of the total — $318,000 against $387 million is basically a rounding error — but it’s a signal that issuers are willing to act quickly when they can identify wallets connected to a major theft.
A Coordinated Mess With a Clear Pattern
The sophistication here wasn’t accidental. State-sponsored groups have been refining these techniques for years, and the Bitget attack seems to fit a well-worn playbook: hit fast, spread funds across chains immediately, use privacy tools and swap services to break the trail, and move into Bitcoin once the dust settles. Chainalysis’s ongoing monitoring of attacker-controlled addresses means the investigation isn’t closed — those funds are still being watched.
What’s maybe most striking is how public blockchain technology cuts both ways. The attackers used it to move funds at speed with no intermediaries. But that same transparency let Chainalysis, Elliptic, and outside observers track every transaction in near real time. The shielded pool attempt in Zcash was probably the closest the hackers got to a true blind spot.
The $1 billion figure for North Korean crypto theft in 2026 alone is worth sitting with for a second. That’s not a rounding error. That’s a funding stream for a sanctioned regime, and the Bitget hack — $387 million in three hours — is now its single biggest contribution.
Chainalysis’s collaboration with Bitget and law enforcement is still active, per available information. No details yet on any recovered funds.
Hub: XRP price, news, and analysis
Frequently Asked Questions
How much was stolen in the Bitget hack and when did it happen?
Hackers took $387 million from Bitget on September 24, moving the funds across Ethereum, XRP, Zcash, and Tron in 23 transactions within the first three hours.
Which firms confirmed the North Korea connection to the Bitget hack?
Chainalysis led the attribution, with Bitget CEO Gracy Chen and blockchain analytics firm Elliptic both noting patterns consistent with North Korean hacker activity.





